When CMMC Phase 2 is paused, what manufacturers should still do on NIST 800-171 and SPRS
What the Phase 2 pause actually changed
In July 2026, the Department of Defense suspended CMMC Phase 2. The big change is about who assesses you, not whether you still have to protect CUI.
During the suspension, requiring activities may generally include only CMMC Level 1 (Self) or Level 2 (Self) in new procurements. Third-party Level 2 (C3PAO) and Level 3 (DIBCAC) designations for new contract requirements are on hold. The November 2026 Phase 2 transition that many teams were planning around is suspended pending reform review.
What did not pause:
- DFARS 252.204-7012 safeguarding and 72-hour cyber incident reporting
- Implementation of NIST SP 800-171 Rev. 2 for covered defense information
- SPRS assessment scores and related self-assessment expectations where your contracts and clauses require them
- Annual affirmations tied to Level 1 / Level 2 self-assessment when your award requires them
- Basic safeguarding of Federal Contract Information under FAR 52.204-21
Official guidance is clear: during the suspension the Department will still enforce baseline compliance with NIST SP 800-171 Rev. 2 through self-assessment and select government-led assessments. If you want the primary source, start with the DoD CIO Implementing Suspension of CMMC Phase II memorandum.
Why manufacturers should not treat this as a free pass
Most manufacturers in the DoD supply chain do not live on certification calendars alone. You live on prime flow-downs, RFQ cybersecurity questionnaires, and whether your SPRS number looks real.
A pause on third-party CMMC designations does not erase:
- Contract language that already requires 7012 / 800-171
- A prime that still demands evidence, an SSP, or a minimum SPRS score before you stay on the bid list
- False Claims Act risk if you affirm a posture you cannot defend
If your drawings, specs, or program data are CUI (or you process Covered Defense Information), the operational work remains the same: scope it, protect it, document it, and score it honestly.
Keep NIST 800-171 moving: a shop-floor checklist
Treat the pause as time to close real gaps, not as a reason to freeze the program. Use this sequence.
1. Reconfirm CUI scope (one page is enough to start)
Write down where CUI enters, where it sits, and where it leaves:
- Email and file shares
- ERP / PLM / MES
- Engineering workstations and CAD vaults
- Shop-floor systems that open drawings or travelers
- Vendor portals and remote access paths
If a CNC controller or tablet opens CUI drawings, it is in scope. "OT is separate" is not a control.
2. Refresh the asset inventory against that boundary
You need an authoritative list of in-scope endpoints, servers, SaaS, and network gear. Stale inventories produce stale SPRS scores.
3. Score all 110 controls against reality
Use NIST SP 800-171A style objectives. Mark each control YES / PARTIAL / NO based on what exists today, not what is "in progress" without evidence.
Then calculate (or recalculate) your SPRS score with the DoD methodology. Do not invent points you cannot show an assessor, a prime, or a government reviewer.
4. Put the gaps in a living POA&M
Every open item needs:
- A named owner
- A target date
- A status someone reviews weekly
An undated POA&M reads as "we will never fix this."
5. Lock an SSP that matches the plant you actually run
Your System Security Plan should describe the current environment, the CUI boundary, residual risk, and how each in-scope control is implemented. If the document and the shop disagree, the shop wins in an assessment. Fix the document or fix the control.
For a manufacturer-oriented walkthrough of this sequence, see The Manufacturer's Guide to NIST 800-171.
SPRS: what "good" looks like while Phase 2 is paused
SPRS is still how many primes and programs size you up. A few operator rules:
- Accuracy beats optimism. An inflated score creates False Claims Act exposure. An honest lower score with a dated POA&M is defensible. A fiction is not.
- Keep the submission current. Know when your last assessment was posted, what score you claimed, and which systems it covered.
- Align score, SSP, and evidence. If SPRS says MFA is implemented, your identity reports and admin accounts should prove it.
- Watch prime thresholds. Many primes want a positive score. Some want closer to 110. Confirm what *your* primes require in writing, not what a LinkedIn thread claims.
During the pause, self-assessment quality matters more, not less. You may not face a C3PAO on day one of every new award, but you can still face government-led review, prime due diligence, and contract clauses that expect 7012 performance.
High-leverage controls manufacturers usually underfund
If bandwidth is limited, prioritize work that closes multiple weighted gaps and reduces real incident risk:
- MFA on remote access, email, and admin accounts
- Unique admin IDs (shared "admin" is a finding waiting to happen)
- FIPS-validated encryption for endpoints and removable media where required
- Centralized logging with retention and actual weekly review
- Incident response that includes 72-hour DoD reporting paths and a recent tabletop
- Vendor flow-down for subcontractors who touch your CUI
These are not "CMMC theater." They are the controls that fail quietly on the plant floor and then show up in RFQs.
What to ask your primes this week
Send a short note (or put it on the next QBRs):
- Which of our current POs or upcoming bids still require DFARS 252.204-7012 / NIST 800-171 evidence?
- Do you still require a minimum SPRS score, and what is it?
- What artifacts do you want on file: SSP, POA&M, SPRS screenshot, policies, or a third-party report?
- If Phase 2 resumes, what lead time do you expect from us?
Do not assume every prime paused their supplier bar because DoD paused Phase 2 designations.
A 30-day plan if you froze the program after the announcement
Week 1: CUI boundary sketch, asset list refresh, pull your last SPRS submission.
Week 2: Control-by-control gap pass on the 110. Recalculate score. Draft or update POA&M owners and dates.
Week 3: Close quick wins (MFA coverage, shared admin cleanup, logging retention, removable media encryption).
Week 4: SSP revisions, IR tabletop date on the calendar, written confirmation of prime expectations.
If you want a structured self-score first, use the free compliance checklist. For the broader CMMC context during the suspension, see our CMMC compliance overview.
Bottom line
CMMC Phase 2 timing is uncertain. Your obligation to safeguard Covered Defense Information is not. Manufacturers that keep NIST 800-171 implementation, honest SPRS scoring, and prime-ready evidence moving will be ready whether Phase 2 stays paused, resumes, or reforms.
If you want a senior engineer to walk your current score and the gaps primes notice first, book a free 45-minute Compliance Gap Audit. You keep the written snapshot either way.